AML, KYC & Financial Crime
A

Authologic

Authologic is a Warsaw headquartered identity infrastructure company founded in 2020 by chief executive Krzysztof Klimczak with Jaroslaw Sygitowicz and chief technology officer Marek Rogozinski, operating through three entities in Poland, the United Kingdom and the United States. It went through Y Combinator in 2021 and raised an 8.2 million dollar Series A in October 2024 led by OpenOcean, with Y Combinator, Peak Capital and SMOK VC participating.

Its platform, OmniID, resolves identity through a single API that automatically selects the best available method, spanning government issued electronic identity schemes, national and private identity wallets including Apple, Google, Samsung and the European Digital Identity Wallet, bank identity systems, open banking data, and conventional document scanning, liveness detection and face matching as fallbacks. Twenty four national and bank schemes are named individually, including mObywatel, Diia, DigiD, itsme, SPID, DNIe, FranceConnect+, Personalausweis, MitID, Freja eID and ID-kaart.

Its central argument is that generative models have broken photograph based document checking, so a cryptographically issued credential that is verified rather than judged is both stronger and more private, disclosing only the attribute required. Zero knowledge proofs verify age and personhood without exposing underlying data, retention rules are set by the customer with the company purging what is no longer needed, and behavioural analysis and fraud scoring sit alongside the routing.

The company publishes ISO 27001, ISO 9001, ISO 22301 and PCI DSS certifications and a PSD2 Account Information Service authorisation, and operates as a trust service provider issuing non qualified electronic attestations of attributes under eIDAS 2.0, with a published trust service policy and status list. Named clients include mElements, the mBank Group ecommerce arm behind Paynow, alongside Intrum, WEALTHON, FONIA Telecom, LV Bet, Santander Leasing and eToro, and the company contributed to Poland's national mObywatel digital identity application, which passed eleven million users. Delivery is through an SDK, a no code link and an API, with self service signup and a free wallet testing environment.

Last VerifiedAugust 20, 2026
Compare Authologic with other vendors
Founded
2020
Headquarters
Warsaw, Poland
Website
authologic.com
Categories
aml-kyc-financial-crime, compliance-and-surveillance, fraud-and-transaction-risk
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

An unusual case where the product thesis is explicitly that inference should be replaced rather than relied upon. The company's argument is that generative models have broken photograph based document checking, and that the answer is a cryptographically issued government credential which is verified rather than judged. Where a national electronic identity or bank identity is available, no model decides anything.

Models do exist around that core, in behavioural analysis and fraud scoring that produces a probability of fraud, and in the document scanning, liveness and face matching methods orchestrated as fallbacks, and those sit inside the regulated operation rather than around it, which is why this is a C rather than a rejection.

But the removal test is decisive: strip them and the aggregation of more than 40 electronic identity schemes, the routing, the fallback logic and the analytics console all remain, and that aggregation is what the company sells.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Nothing describes human oversight of an outcome. What exists is routing rather than review: verification scenarios can be defined flexibly against the risk profile of the client or the process, and automatic fallback moves a user to another method when one fails. Both are resilience and configuration mechanisms, not controls over a decision.

No confidence threshold, escalation path, manual review queue, abstention behaviour or appeal step is described, and nothing states what happens to a person no available method can verify, which is the consequential case in a product whose premise is that some users will not hold a digital credential.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy rate, false accept or false reject figure, benchmark, independent test or evaluation methodology was located for the fraud scoring layer or for the orchestrated document, liveness and face matching methods, and no validation material exists for a customer's own model risk function.

The gap matters most for the fraud probability score, which is the one place the platform produces a judgment of its own rather than passing through a cryptographic verification, and nothing describes how that score is calibrated, what a given value means, or how a customer should set a threshold on it.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Named customers carrying a published outcome, which is the bar this axis sets. Five clients appear on the company's own site with their own case material: mElements, the ecommerce arm of the mBank Group operating the Paynow service, alongside LV Bet, Intrum, WEALTHON and FONIA Telecom, and Santander Leasing and eToro are named in independent coverage.

The mElements case study attaches a figure to the name, describing business onboarding reduced to five minutes and manual document checking replaced by an automated flow that met the group's data processing requirements, which is a named regulated buyer, a stated result and a described mechanism rather than a logo.

Independent trade press separately corroborates the company's contribution to Poland's national digital identity application, which passed eight million and later eleven million credentials, and corroboration by a party with no commercial interest is stronger evidence than anything a vendor publishes about itself.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Nothing states whether verification records, document images, biometric captures, credential assertions or open banking data are retained after a check, reused, or used to train or improve the behavioural analysis and fraud scoring models. The silence is notable given that the company's own privacy argument is about limiting what a business receives about a person, which addresses the customer's exposure to the data and not the vendor's own retention of it. Nothing describes whether fraud signals are pooled across the client base, which is the shared corpus question this index has asked of every vendor holding data from many institutions.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

Substantive and architectural rather than a policy assertion, which is rare on this axis. Three commitments are published. Retention is customer controlled, with the company stating that clients set their own retention rules and that it purges what is no longer needed, described as clean by default and auditable by design, which is a concrete answer to the question most vendors in this index leave open.

Disclosure is attribute level, pulling only the attributes a given request needs rather than a whole identity record. And zero knowledge proofs are used to verify age and personhood without exposing the underlying data at all, so for those checks the data never moves. A published trust service privacy policy sits alongside the general one.

Held below an A because no subprocessor list, no stated retention default, and no data processing agreement terms were located, and because the open banking route retrieves account and transaction data whose specific handling is not described.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Four audited certifications are enumerated in the company's own material under a certificates and licences heading: ISO 27001 for information security, ISO 9001 for quality management, ISO 22301 for business continuity, and PCI DSS. ISO 22301 is uncommon in this index and is a meaningful inclusion for a supplier whose outage would stall customer onboarding entirely.

Held at B rather than A because the presentation is thin where the strongest vendors in this pocket are specific: no edition or version is given for any standard, no certificate number, no attesting or accrediting body is named, no assessed level is stated for PCI DSS, and there is no trust portal or status page carrying the underlying reports.

One credential test observation recorded rather than deducted a second time: the same row places a GDPR mark alongside the four certifications, and GDPR is a regulation no body certifies against, which is the mixed badge row shape this index has catalogued elsewhere.

Regulatory Status and Licensure
AA on Regulatory Status and LicensureThe regulatory position is stated and a formal admission process stands behind it: a register entry, an eCBSV enrolment, a payment network partner admission, or presence inside SAR or CTR filing paths.
Vendor Published

Confirmed in the company's own material and the first A on this axis in the business verification pocket. Two distinct forms of standing sit inside the regulatory perimeter rather than beside it. The company publishes a PSD2 Account Information Service authorisation among its certificates and licences, which is an authorisation granted and supervised by a national competent authority, carrying professional indemnity requirements and continuing supervision, not an enrolment in an access programme.

Separately it operates as a trust service provider under the European identity framework, publishing a trust service policy for the issuance of non qualified electronic attestations of attributes, a set of trust service terms, and a status list, which is the revocation infrastructure such an issuer must maintain. That is a formal role inside the eIDAS architecture with published governing documents rather than a conformity claim about a product.

This index has held that a licensed and directly supervised firm stands apart from a software supplier that merely serves supervised customers, and that reasoning applies here. Held at A rather than higher only in the sense that no financial regulator supervises the verification models themselves.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness disclosure and no evaluation of outcomes across populations. The exposure here is distributional rather than algorithmic and the company's own published analysis describes it without addressing it: national digital identity adoption is deeply uneven, with the French scheme at 3.2 million credentials against more than eleven million users of the Polish one.

Where a credential is scarce, users fall back to document and biometric methods, so the population routed to the weaker path is systematically different, skewing older, poorer, more rural and more foreign. Nothing published examines whether verification outcomes differ across those routes, which is the fairness question this architecture creates.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Nothing states who bears the cost of a wrong outcome or how a person contests one. The orchestration model divides the question further than usual, since a failed verification may originate in a government identity scheme, a bank identity provider, an orchestrated document or biometric supplier, or the fraud scoring layer, and the person refused sees only a rejection from the business they approached. No notice, no explanation of which method or signal produced the result, and no correction route is described at any layer.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The identity supply chain is disclosed in unusual detail, with national electronic identity schemes, bank identity systems and named wallet platforms enumerated, and the model supply chain is not disclosed at all. No provider, family or version is named for the behavioural analysis, the fraud scoring, or the document, liveness and face matching capability, and nothing states which of those are built in house and which are orchestrated from third parties. This is now the third orchestration vendor recorded in this pocket that names what supplies its data and says nothing about what supplies its inference.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration is the product and the catalogue is published by name rather than by count, which is what earns the A. Twenty four national and bank identity schemes are listed individually, among them mObywatel in Poland, Diia in Ukraine, DigiD and IDIN in the Netherlands, itsme in Belgium, SPID in Italy, DNIe in Spain, FranceConnect+ in France, Personalausweis in Germany, MitID in Denmark, MinID in Norway, Freja eID in Sweden, FINeID in Finland, ID-kaart in Estonia, SwissID, LuxTrust, ID Austria, MyGovID in Ireland and OneID in the United Kingdom.

Each is a separate technical and legal integration with its own protocol and consent model, which is materially harder than adding a supplier API. Apple, Google and Samsung wallets are supported alongside the European Digital Identity Wallet, and a free browser based wallet playground lets a buyer test those flows before contracting.

Three integration routes are offered, an SDK installable from the public package registry, a no code link, and an API with public developer documentation, with automatic fallback between methods so a failed route does not end the journey.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

A hosted multi tenant platform with no published deployment or residency detail: no cloud provider, region or jurisdiction named, no private or single tenant option, and no statement of where verification records, credential assertions or open banking data rest.

The omission is more pointed here than for most vendors because the company operates across more than 200 countries while brokering credentials issued by sovereign identity schemes, several of which impose their own conditions on where derived data may be processed, and because its own positioning rests on European digital identity standards where data location is a live regulatory question.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing published at any level and no statement of the charging basis, which is a real gap for an orchestration product because the underlying methods differ enormously in cost, with a national electronic identity check, an open banking retrieval and a document plus liveness check carrying different economics, and a buyer cannot tell whether they pay per verification, per method, per market or on a platform fee. A live demonstration and a widget trial are offered, so the product can be seen before contracting even though its cost cannot.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Roughly 80 clients across financial services, gaming and betting, telecoms, crypto and ecommerce, with marquee names disclosed including Santander Leasing, eToro, Superbet and LV Bet, and offices in Warsaw, London and San Francisco supporting expansion into the United Kingdom, Latin America and the Middle East. Reach is stated as more than 50 verification methods across more than 200 countries.

The strongest single coverage signal is not commercial: the company contributed to Poland's national mObywatel digital identity application and its mDowod credential, which passed eight million users, later exceeding eleven million. Working inside a sovereign identity programme at national scale is a form of institutional reach almost nothing else in this index can claim.

Alternatives to Authologic

The closest documented capability profiles to Authologic in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Commercial Transparency and Model Supply Chain Disclosure where Authologic does not

Documents Autonomy and Oversight Model and Model Risk Management and Transparency, among others where Authologic does not

Documents AI Centrality and Commercial Transparency, among others where Authologic does not

Documents Commercial Transparency and Autonomy and Oversight Model, among others where Authologic does not

Documents AI Centrality and Model Risk Management and Transparency where Authologic does not

Documents Autonomy and Oversight Model where Authologic does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746